Depth 28.1 · Security and compliance readiness · Level 3

NIS2 and DORA readiness

NIS2 and DORA readiness is preparation for two EU laws on cybersecurity and operational resilience. NIS2, Directive (EU) 2022/2555, sets security and incident reporting duties for medium and large organisations in sectors listed in the Directive, such as energy, transport, health and digital infrastructure. DORA, Regulation (EU) 2022/2554, sets rules on managing technology risk for financial entities in the EU and for some of their technology suppliers. UK organisations fall under the UK NIS Regulations 2018 and the ICO regime instead, so which set applies depends on where you operate. Whether any of them applies to your company is a legal question for your counsel; our work is preparation, not legal advice.

Specification

Input
Your counsel's view on which law applies, current security policies, system and supplier inventories, and incident procedures.
Method
We break the relevant text into individual requirements, map each to the systems and teams involved, record whether a working control exists, and note the evidence that shows it.
Deliverable
Control gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.
Measured by
Requirements with a working control and current evidence, and gaps closed against their planned dates.

Most often bought inPayments and fintech, Logistics and supply chain

The artefact, before and after

Control gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.

Before: a blank NIS2 and DORA readiness record with a row for each of requirement breakdown from directive (eu) 2022/2555 or regulation (eu) 2022/2554, mapping to systems and teams, incident handling and reporting procedures, supplier and third party risk review, gap register with owners, and no entries. After: every row carries a finding and a checked status, which is the state the work hands over.

Typical first engagement

The usual order of a first piece of work. Timing and price are set at scoping, once we have seen the stack.

  1. 01Scope with counselYou get: Your counsel's view on which law applies, recorded as the starting point.
  2. 02Requirement registerYou get: Each relevant requirement listed in plain language.
  3. 03Gap registerYou get: Each requirement mapped to a control, an owner, evidence and a status.
  4. 04Remediation planYou get: Open gaps ordered by risk, as preparation only and not certification.

Security and compliance readiness

Next in this line

Ask about this part of the stack

Write one question about NIS2 and DORA readiness in your own systems. We answer it in writing and name what we would need to see to answer it properly.

Send one question

A written reply, no call needed.